Are you in scope?
Check where your organisation operates, where the AI is placed on the market and where its output is used.
Run the scope check
A plain-language route from AI use case to risk level, legal role and audit-ready evidence without reading the entire Regulation first.
Do not begin with a 100-page policy. First determine scope, role and risk. Those three decisions control the rest of your workload.
Check where your organisation operates, where the AI is placed on the market and where its output is used.
Run the scope check →A buyer using Copilot is usually a deployer. A company selling an AI tool under its own name may be a provider. Duties differ.
Identify your role →Classify the actual use case not only the product name. The same model can be low-risk in one workflow and high-risk in another.
Screen the use case →Answer three preliminary questions. This is a triage tool, not a legal determination.
If at least one answer is “yes”, the Act may apply. Your next step is to determine your legal role and classify each use case.
Choose the description that best matches your organisation. You can hold more than one role for different systems.
You use an AI system under your authority in a professional context for example Microsoft Copilot, an HR screening tool or an AI-enabled service desk.
“We use ChatGPT” is not a risk classification. Document what the AI does, whose rights it can affect and how humans use its output.
You will receive a preliminary direction and the first evidence to collect.
Formal classification depends on the system’s intended purpose, context, exclusions and your role.
The July 2026 AI Omnibus extended the high-risk dates. It did not pause obligations that already apply.
The phased implementation period began.
CompletedProhibited practices, relevant definitions and Article 4 AI literacy measures began to apply.
Applies nowGovernance rules and obligations for providers of general-purpose AI models began to apply.
Applies nowArticle 50 transparency requirements and enforcement powers became applicable, alongside other core provisions.
Applies nowHigh-risk obligations for listed use cases such as employment, education and essential services begin to apply under the revised timeline.
Prepare nowHigh-risk obligations apply to AI systems that are safety components of products covered by specified EU product legislation.
Future datePrioritise traceable evidence over policy volume. An auditor needs to see what exists, who owns it, how it was assessed and what controls operate.
Name an executive owner, create an AI inventory, identify unsanctioned tools and pause any suspected prohibited practice.
Document intended purpose, legal role, risk class, data use, vendor and accountable system owner for every use case.
Implement human oversight, transparency notices, approved-use rules, vendor controls and role-based AI literacy measures.
Centralise approvals, training records, FRIAs/DPIAs, incident logs, testing and board reporting in a controlled evidence repository.
Review new systems, vendor changes, incidents, risk classifications, controls and upcoming regulatory guidance.
Your selections are stored only in this browser. No checklist data is submitted.
Authorities consider the infringement’s nature, gravity and duration. Commercial consequences can include delayed procurement, failed due diligence and suspended deployments.
Up to €35 million or 7% of total worldwide annual turnover for the preceding financial year, subject to the statutory calculation.
Up to €15 million or 3% for non-compliance with specified operator, notified-body and transparency obligations.
Up to €7.5 million or 1% for incorrect, incomplete or misleading information supplied in response to certain official requests.
AI-enabled Microsoft services can fall within the AI Act, but the duties depend on the product, feature, intended use and your role. Most customer organisations will be deployers. Inventory the exact feature and workflow — for example drafting, HR screening or customer interaction — and classify that concrete use.
No. High-risk classification is tied to defined product categories and listed use cases, subject to conditions and exceptions. Many routine systems are not high-risk, although AI literacy, transparency, GDPR, security and internal governance may still apply.
No. A FRIA is not universal for every AI system or every deployer. Article 27 applies to specified deployers and high-risk uses. Separately, a GDPR Data Protection Impact Assessment may be required where personal-data processing is likely to create high risk. Record the decision even when an assessment is not required.
No. The AI Act does not make AIGP certification a mandatory corporate role or statutory condition for compliance. Certification can demonstrate knowledge, but evidence of appropriate governance, competent people and operating controls matters more than a badge alone.
No. Prohibitions, AI literacy, GPAI-related rules, Article 50 transparency requirements and enforcement are already active. The extension creates preparation time for high-risk duties; it does not remove current obligations or your exposure under GDPR, consumer, employment and sector law.
Potentially yes. The Act can apply to non-EU providers placing AI systems or GPAI models on the EU market and to providers or deployers where system output is used in the EU. Confirm the exact territorial connection and any applicable exclusion.
A controlled AI inventory with an owner, intended purpose, legal role, risk class, vendor, data categories and status for every system. It becomes the index for approvals, FRIAs, DPIAs, contracts, training, incidents and board reporting.
Start with the Boardroom Diagnostic, or book a focused readiness call to map your fastest route to audit-ready AI governance inside Microsoft 365.
Reviewed against official EU sources available on 3 August 2026. This guide provides general information and a preliminary triage only. It does not replace a system-specific legal, technical or conformity assessment.